16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 11: Policer <strong>Configuration</strong><br />

NOTE: J Series Services Routers do not support prefix-specific actions.<br />

Examples: Configuring Policer Actions for Specific Address Prefixes<br />

Create a prefix-specific policer operating on the source address and apply it to the input<br />

interface:<br />

[edit]<br />

firewall {<br />

policer host-policer {<br />

filter-specific;<br />

if-exceeding {<br />

bandwidth-limit bps;<br />

burst-size-limit bytes;<br />

}<br />

then {<br />

discard;<br />

}<br />

}<br />

family inet {<br />

prefix-action ftp-policer-set {<br />

count;<br />

destination-prefix-length 32;<br />

policer host-policer;<br />

subnet-prefix-length 24;<br />

}<br />

filter filter-ftp {<br />

term term1 {<br />

from {<br />

destination-address 10.10.10/24;<br />

destination-port ftp;<br />

}<br />

then {<br />

prefix-action ftp-policer-set;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

Filter all packets going to the /24 subnet, letting them pass to the prefix-specific action<br />

policers. In the policer set, the last octet of the source address field of the packet is used<br />

to index into the respective prefix-specific action policers.<br />

[edit]<br />

firewall {<br />

policer 1Mbps-policer {<br />

if-exceeding {<br />

bandwidth-limit 1m;<br />

burst-size-limit 63k;<br />

}<br />

}<br />

family inet {<br />

prefix-action per-source-policer {<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

299

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!